rdmsm4x-changelog-20260923-1820-firewall-stays-on-fleet-rule
rdmsm4x-changelog-20260923-1820-firewall-stays-on-fleet-rule
Recorded fleet-wide that the macOS Application Firewall stays ON; Rich re-enabled it on rdmsm4x after an agent left it off.
- Window: 2026-09-23 18:15–18:20 EDT, rdmsm4x
- Measured:
socketfilterfw --getglobalstate→ State = 1 on all 6 hosts (18:15 EDT). - Who disabled it on rdmsm4x: unknown — unified log (4d) holds no
state-change event. Tyrell's preflight test forbids
setglobalstate off, so that match was not the cause. - FLEET.md: appended section "macOS Application Firewall stays ON, every Mac" (+22 lines, 539→561). Commit e7aeb3f in fleet/maintenance.
- Distributed with sync_fleet_knowledge.zsh (dry run, then real run, rc 0). FLEET.md sha256 5116f9ddd44d030d on 6/6; agent context files unchanged.
- Ticket ISSUE-20260923-07 (INCIDENT) opened and resolved with evidence.
- Claude memory: firewall-stays-on.md.
- Undo: git revert e7aeb3f in fleet/maintenance, then re-run sync_fleet_knowledge.zsh.